This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Missing mysqld.sock
#8
[Solved] RE: Missing mysqld.sock
(07-01-2025, 09:09 AM)rsthomas Wrote: Yep, all was well since Saturday afternoon -- until this afternoon when the server filled up again!

Looking at /var/log/syslog it appears I have been hacked by some maggots using me as their private email server.

If you don't mind, can I pick your brain again?

Mysql seems to still be running, as I haven't rebooted the server.  Trying to run it tells me this:  ERROR 1045 (28000): Access denied for user 'root'@'localhost' (using password: NO).  Do I need to include the password somewhere in the command line?

1.) I expect there is a file on the server that is running the show.  Any idea how I can locate it?

2.) It might be using a database table or text file to provide the addresses

3.) Is there a way I can delete the email log file in order to recover some space?

At any rate, things have settled down now since the hackers might be done for the day.

I can resize the hard drive to get the domains/sites to come up but unless I delete the script and/or email list file it will just fill up again.  With your expert advice, hopefully I can delete the files that are causing the problem.

Thanks in advance for your help!

I'll check it out. 
You can edit the large log file and delete it's contents and save it. Thats what I do when I'm testing.
Send me a PM with your hosting domain, and the domain you think is causing the problems.
If you have a site that has vulnerable code, they could be getting in that way.
If you have an older backup of your hostdata folder, you could try and compare the old one vs the new one and see what files are new or don't belong or what files are larger than they are supposed to be.
We had a similiar issue happen with our docs site. A hacker was able to get in through an old no longer supported WYSIWYG editor. (Like the one one here with the bold, italilic, etc.)

On another note, could you use a different editor for the log files you send me? Something like notepad++ ?
I don't have a decent docx viewer/reader unfortunately.
-TGates - Project Council

SEARCH the Forums or read the DOCUMENTATION before posting!
Support Sentora and Donate: HERE

Find my support or modules useful? Donate to TGates HERE
Developers and code testers needed!
Contact TGates for more information
Reply
Thanks given by:


Messages In This Thread
Missing mysqld.sock - by rsthomas - 06-27-2025, 06:15 AM
RE: Missing mysqld.sock - by TGates - 06-27-2025, 09:59 AM
RE: Missing mysqld.sock - by rsthomas - 06-27-2025, 10:15 PM
RE: Missing mysqld.sock - by TGates - 06-29-2025, 07:01 AM
RE: Missing mysqld.sock - by rsthomas - 07-01-2025, 04:40 AM
RE: Missing mysqld.sock - by TGates - 07-01-2025, 07:09 AM
RE: Missing mysqld.sock - by rsthomas - 07-01-2025, 09:09 AM
RE: Missing mysqld.sock - by TGates - 07-01-2025, 03:16 PM
RE: Missing mysqld.sock - by rsthomas - 07-04-2025, 05:58 AM

Forum Jump:


Users browsing this thread: 1 Guest(s)